Vulnerability index

Browse CVEs

1,035 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

GitLab HIGH 7.5
CVE-2022-1510

An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all ve…

Fix: 14.8.6 / 14.9.4+
Fix from $1,950 2022-05-11
GitLab MEDIUM 6.1
CVE-2022-1433

An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all ve…

Fix: 14.8.6 / 14.9.4+
Fix from $1,600 2022-05-11
GitLab MEDIUM 6.5
CVE-2022-1406

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 all…

Fix: 14.8.6 / 14.9.4+
Fix from $1,600 2022-05-11
GitLab MEDIUM 5.3
CVE-2022-1352

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and …

Fix: 14.8.6 / 14.9.4+
Fix from $1,600 2022-05-11
GitLab MEDIUM 5.3
CVE-2022-1431

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all v…

Fix: 14.8.6 / 14.9.4+
Fix from $1,600 2022-05-10
GitLab MEDIUM 6.5
CVE-2022-1185

A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and 14.9.0 to 14.9.2 allows an a…

Fix: 14.7.7 / 14.8.5+
Fix from $1,600 2022-04-04
GitLab MEDIUM 6.1
CVE-2022-1175EPSS 82%

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starti…

Fix: 14.7.7 / 14.8.5+
Fix from $1,600 2022-04-04
GitLab MEDIUM 5.4
CVE-2022-1190EPSS 87%

Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to e…

Fix: 14.7.7 / 14.8.5+
Fix from $1,600 2022-04-04
GitLab MEDIUM 5.3
CVE-2022-1188

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions starting from 14.8 before 14.8.5, …

Fix: 14.7.7 / 14.8.5+
Fix from $1,600 2022-04-04
GitLab CRITICAL 9.8
CVE-2022-1162EPSS 76%

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.…

Fix: 14.7.7 / 14.8.5+
Fix from $2,300 2022-04-04
GitLab HIGH 7.5
CVE-2022-1174

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions…

Fix: 14.7.7 / 14.8.5+
Fix from $1,950 2022-04-04
GitLab MEDIUM 6.5
CVE-2022-1120

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed …

Fix: 14.7.7 / 14.8.5+
Fix from $1,600 2022-04-04
GitLab MEDIUM 6.5
CVE-2022-1148

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 pr…

Fix: 14.7.7 / 14.8.5+
Fix from $1,600 2022-04-04
GitLab MEDIUM 5.3
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 …

Fix: 14.7.7 / 14.8.5+
Fix from $1,600 2022-04-04
GitLab HIGH 7.6
CVE-2022-0425

A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 allows an attacker to trigger Se…

Fix: after 14.7.1
Fix from $1,950 2022-04-01
GitLab HIGH 7.5
CVE-2022-0741

Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal environment variables via specia…

Fix: 14.6.5 / 14.7.4+
Fix from $1,950 2022-04-01
GitLab MEDIUM 5.7
CVE-2022-0489

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature w…

Fix: 14.6.5 / 14.8.2+
Fix from $1,600 2022-04-01
GitLab HIGH 7.5
CVE-2021-39908

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4…

Fix: 14.2.6 / 14.3.4+
Fix from $1,950 2022-04-01
GitLab CRITICAL 9.8
CVE-2022-0735EPSS 13%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4,…

Fix: 14.6.5 / 14.7.4+
Fix from $2,300 2022-03-28
GitLab CRITICAL 9.1
CVE-2022-0249

A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since requests to shared address spac…

Fix: after 14.7.1
Fix from $2,300 2022-03-28
GitLab HIGH 8.8
CVE-2022-0427

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitra…

Fix: 14.5.4 / 14.6.4+
Fix from $1,950 2022-03-28
GitLab HIGH 8.8
CVE-2022-0751

Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleadi…

Fix: 14.6.5 / 14.7.4+
Fix from $1,950 2022-03-28
GitLab HIGH 8.1
CVE-2022-0136

A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnerable to a blind SSRF attack th…

Fix: after 14.7.1
Fix from $1,950 2022-03-28
GitLab HIGH 7.5
CVE-2022-0738

An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all ve…

Fix: 14.6.5 / 14.7.4+
Fix from $1,950 2022-03-28
GitLab MEDIUM 6.8
CVE-2022-0123

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not val…

Fix: 14.4.5 / 14.5.3+
Fix from $1,600 2022-03-28
GitLab MEDIUM 6.5
CVE-2022-0549

An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starti…

Fix: 14.6.5 / 14.7.4+
Fix from $1,600 2022-03-28
GitLab MEDIUM 6.1
CVE-2022-0283

An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a…

Fix: 14.5.4 / 14.6.4+
Fix from $1,600 2022-03-28
GitLab MEDIUM 5.3
CVE-2021-4191EPSS 80%

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with res…

Fix: 14.6.5 / 14.7.4+
Fix from $1,600 2022-03-28
GitLab HIGH 8.0
CVE-2022-0154

An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all v…

Fix: 14.4.5 / 14.5.3+
Fix from $1,950 2022-01-18
GitLab HIGH 7.5
CVE-2022-0244

An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due…

Fix: after 14.6.2
Fix from $1,950 2022-01-18